Playbook Responding Ransomware M365 Defender
In brief
The playbook now refers to Microsoft Defender instead of Microsoft Defender XDR when describing consolidated visibility into impacted or at-risk assets, and updates the linked article title accordingly.
What Defender admins need to know
No administrator action is required. Use the updated Microsoft Defender terminology when following the playbook.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Step 1: Assess the scope of the incident
Run through this list of questions and tasks to discover the extent of the attack. Microsoft Defender XDR can provide a consolidated view of all impacted or at-risk assets to aid in your incident response assessment. See Incident response with Microsoft Defender. You can use the alerts and the evidence list in the incident to determine:
- Which user accounts might be compromised?
- Which accounts were used to deliver the payload?
@@ -34,7 +34,7 @@ Containment and investigation should occur as simultaneously as possible; howeve ### Step 1: Assess the scope of the incident -Run through this list of questions and tasks to discover the extent of the attack. Microsoft Defender XDR can provide a consolidated view of all impacted or at-risk assets to aid in your incident response assessment. See [Incident response with Microsoft Defender XDR](incidents-overview.md). You can use the alerts and the evidence list in the incident to determine:+Run through this list of questions and tasks to discover the extent of the attack. Microsoft Defender can provide a consolidated view of all impacted or at-risk assets to aid in your incident response assessment. See [Incident response with Microsoft Defender](incidents-overview.md). You can use the alerts and the evidence list in the incident to determine: * Which user accounts might be compromised? * Which accounts were used to deliver the payload? 